Export limit exceeded: 376577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376577 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18030 | 2 Bricksforge, Wordpress | 2 Bricksforge, Wordpress | 2026-08-11 | 8.1 High |
| The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account. Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used. | ||||
| CVE-2026-17540 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | 8.8 High |
| The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service. | ||||
| CVE-2026-17435 | 1 Rrwo | 1 File::rotate::simple | 2026-08-11 | 2.5 Low |
| File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target. An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated). Note that the touch option is disabled by default. | ||||
| CVE-2026-17023 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-11 | 4.8 Medium |
| The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature. | ||||
| CVE-2026-17021 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-11 | 5.3 Medium |
| The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. | ||||
| CVE-2026-17020 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-11 | 4.3 Medium |
| The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers. | ||||
| CVE-2026-17018 | 2026-08-11 | 4.9 Medium | ||
| The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators. | ||||
| CVE-2026-17016 | 2026-08-11 | 3.7 Low | ||
| The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled. | ||||
| CVE-2026-17012 | 2026-08-11 | 5.3 Medium | ||
| The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's. | ||||
| CVE-2026-16985 | 2026-08-11 | 8.8 High | ||
| The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution. | ||||
| CVE-2026-16949 | 2026-08-11 | 5.8 Medium | ||
| The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks. | ||||
| CVE-2026-16299 | 2026-08-11 | 9.8 Critical | ||
| The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | ||||
| CVE-2026-16298 | 2026-08-11 | 9.8 Critical | ||
| The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | ||||
| CVE-2026-16257 | 2026-08-11 | 8.2 High | ||
| The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information. | ||||
| CVE-2026-16230 | 2026-08-11 | 9.8 Critical | ||
| The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions. | ||||
| CVE-2026-15238 | 2 Motopress Hotel Booking, Wordpress | 2 Motopress Hotel Booking, Wordpress | 2026-08-11 | 5.4 Medium |
| The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier. | ||||
| CVE-2026-15237 | 2 Motopress Hotel Booking, Wordpress | 2 Motopress Hotel Booking, Wordpress | 2026-08-11 | 5.3 Medium |
| The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid. | ||||
| CVE-2026-14941 | 2026-08-11 | 5.4 Medium | ||
| The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration. | ||||
| CVE-2026-14860 | 2026-08-11 | 5.3 Medium | ||
| The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML. | ||||
| CVE-2026-14211 | 2 Ameliabooking, Wordpress | 2 Booking For Appointments And Events Calendar, Wordpress | 2026-08-11 | 3.8 Low |
| The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers. | ||||